Security and release integrity

Know what you install.

Mochi publishes its source, release history, distribution contract, and checksum so you can verify the Mac app before opening it.

Current release

Version
0.1.1
Download size
Approximately 4.1 MB
Requires
macOS 13 or later; Apple silicon or Intel
SHA-256
9d52e2a92b458b47756f5096ebe2b9950b3667d751a157259630f013241bc86d

Compare the checksum with the value attached to the canonical GitHub release. In Terminal, run shasum -a 256 ~/Downloads/Mochi.dmg. Do not install if the values differ.

A checksum proves that your download matches the published artifact; it does not by itself prove who created the artifact. Check the release tag, repository, macOS developer identity, and notarization result as separate signals.

Signing and notarization

The release workflow is designed to sign with an Apple Developer ID, notarize the DMG, staple the notarization ticket, and reuse one immutable artifact across channels. Verify the current release itself rather than relying only on this page: macOS should identify the developer when you open the app, and the GitHub release should publish the matching checksum.

The repository’s distribution contract makes GitHub Releases the canonical owner of the DMG, versioned archive, checksum, and release manifest. Other channels should point to or reuse that same artifact rather than rebuilding it.

App boundaries

Mochi receives access only to folders you choose. Credentials are stored in macOS Keychain. AI providers return suggestions, not filesystem instructions; the client validates destinations and owns every file operation. Existing files are not silently overwritten, and filesystem safety regressions are release blockers.

Rules, review decisions, undo history, and folder bookmarks stay on the Mac. Provider requests contain a limited, locally prepared description instead of complete file uploads. Read the privacy policy for the precise fields and processors.

Release and dependency practices

One immutable Git tag is intended to produce one universal macOS build. Verification compares the public checksum with the release manifest. The app targets both Apple silicon and Intel and records its minimum macOS version in release metadata.

Open source makes inspection possible, but it is not a substitute for verification. Review the repository history, current issues, security policy, and release notes. Download from the link on this site or the canonical repository rather than a third-party mirror.

Report a vulnerability

Please do not publish an unpatched vulnerability. Use GitHub private security advisories or email trymochi.dev@gmail.com with reproduction steps and impact. See the security policy for the supported version and response process.

Include the affected Mochi version, macOS version, expected behavior, and a minimal reproduction. Remove private filenames or file contents unless they are necessary and you are comfortable sharing them privately.